How to Spot a Phishing Email

Learn how to spot a phishing email: six red flags to watch for, realistic scam examples, plus step-by-step actions to take if you already clicked a link.

How to Spot a Phishing Email

Phishing emails are one of the most common ways criminals steal passwords, banking details, and personal information. Knowing how to spot a phishing email takes just a few minutes to learn, yet it can save you from identity theft, drained accounts, and months of cleanup. This guide walks you through the red flags to watch for, realistic examples of common tricks, and what to do if you already clicked.

What Is a Phishing Email?

A phishing email pretends to come from a trusted source — your bank, a shipping company, or even your own employer. Its goal is to make you hand over sensitive information or click a link that installs malware. There are also targeted variants: spear phishing is aimed at a specific person and often uses details gathered from social media to seem credible. Either way, the defenses are the same.

Red Flag 1: Urgent or Threatening Language

Legitimate companies rarely pressure you with panic. Phishing emails lean on urgency so you act before thinking. Watch for phrases like:

  • “Your account will be suspended within 24 hours unless you verify now.”
  • “Unauthorized login attempt detected — secure your account immediately.”
  • “Your package could not be delivered. Click here within 48 hours or it will be returned.”

A real bank or service will typically let you log in normally and check for alerts yourself. If an email insists you must act right this second, slow down — that is exactly the reaction the sender wants.

Red Flag 2: A Suspicious Sender Address

The display name might say “PayPal Support,” but the actual address tells the real story. Always expand or hover over the sender name to see the full address.

Realistic examples of fake addresses:

  • support@paypa1-secure.com — a lookalike domain with the number 1 instead of the letter l
  • no-reply@amaz0n-orders.net — a zero instead of the letter o, plus an unfamiliar ending
  • security-team@gmail.com — a free email account, which banks and large companies almost never use for official mail

If the domain does not match the company’s official website exactly, treat the message as hostile. When in doubt, open a new browser tab and navigate to the company’s site yourself.

Red Flag 3: Generic Greetings

Mass phishing emails usually begin with “Dear Customer,” “Dear User,” or simply “Hello.” Legitimate services that know your name normally use it.

Be especially cautious with emails that use no greeting at all and jump straight to a demand or a link.

Red Flag 4: Links and Attachments That Don’t Add Up

Hover over any link (on desktop) or press and hold it (on mobile) to preview the destination before clicking. Attackers disguise malicious URLs behind innocent-looking button text.

For example, a button labeled “Verify Account” might actually point to http://secure-verify-account-random-string.example instead of the company’s real domain. Also beware of:

  • Shortened URLs (like bit.ly links) in supposedly official mail — legitimate companies rarely hide their domain
  • Attachments you did not expect, especially .zip, .exe, or Office documents with macros — these can install malware when opened
  • Misspelled domains in links: micros0ft.com, netfl1x.com, faceb00k.com

A safe habit: never click through from the email. Type the address yourself or use the app you already have installed.

Red Flag 5: Poor Grammar and Odd Formatting

Professional companies proofread their customer communications. Phishing emails frequently contain:

  • Awkward phrasing or sentences that read like machine translation
  • Inconsistent fonts, strange capitalization, or blurry, low-resolution logos
  • A reply-to address that differs from the sender address

This is not a perfect test — some phishing emails are polished. But combined with the other flags, it strengthens the case that something is wrong.

Red Flag 6: Requests for Sensitive Information

No reputable company asks for your password, full card number, or similar details by email. Ever. If a message asks you to reply with credentials or “update your payment details” through a form, it is phishing — delete it.

Similarly, beware of emails asking you to buy gift cards, wire money, or download remote-access software. These are staples of business email compromise scams, where the attacker poses as a boss or vendor.

A Quick Checklist to Spot a Phishing Email

Before clicking anything in an unexpected email, run through this:

  1. Do I recognize the exact sender domain?
  2. Was I expecting this message?
  3. Is it creating urgency or fear?
  4. Does the link preview match the real website?
  5. Can I verify it independently (official app, typed URL, known phone number)?

If any answer worries you, stop and verify through a separate channel.

What to Do If You Clicked

It happens — even careful people click sometimes. Speed matters, so act in this order:

  • Disconnect and stop interacting. Close the tab or email. Do not enter any more information.
  • Change your password immediately on the real site — and anywhere else you reused that password. Going forward, use a password manager so each account has a unique password.
  • Turn on two-factor authentication on the affected account. This alone blocks most account takeovers even when a password is stolen.
  • If you entered payment details, contact your bank or card provider right away to freeze the card and watch for fraudulent charges.
  • Report the phishing email. Most email providers have a “Report phishing” option; forwarding it to your IT team or local cybercrime reporting service helps protect others too.
  • Scan your device with reputable antivirus software in case the click downloaded malware.

FAQ

Q: Can a phishing email infect my device just by opening it?
A: Simply opening a plain-text email is very rarely enough to cause infection. The danger comes from clicking links or opening attachments. That said, keep your email client updated, because rare vulnerabilities do exist.

Q: What should I do with a phishing email I received?
A: Do not click anything. Mark it as phishing or spam in your email app, which also trains the filter. If it impersonates a company you use, forward it to that company’s official abuse or phishing reporting address.

Q: How can I check if a link is safe without clicking it?
A: On a computer, hover over the link to preview the full URL in the status bar. On a phone, press and hold the link to see a preview. Look for the real company domain at the start of the address, and watch for misspellings, extra words, or strange endings.

Q: I entered my password on a fake site. Is changing it enough?
A: Change it immediately on the real site, and change it anywhere else you reused it. Also enable two-factor authentication and review the account for unfamiliar activity, such as new devices, changed recovery email addresses, or sent messages you did not write.

Conclusion

Learning to spot a phishing email comes down to a simple mindset: verify, don’t trust. Check the sender, inspect links before clicking, resist manufactured urgency, and never hand over sensitive details by email. Make the 30-second checklist a habit, and you will dodge the vast majority of phishing attempts — and know exactly what to do on the rare occasion one slips through.